Skip to content
Cybersecurity Engineer · IAM/PAM & systems

Hello, I'm

Yann-Désiré Kouassi

Cybersecurity Engineer · IAM/PAM & systems

IAM / PAMSécurité réseauInfrastructureDevSecOps

I secure the critical infrastructure and privileged access of major telecom, banking and institutional accounts, across Africa and Europe.

4+
years of experience
12+
client deployments
3+
countries served
10+
certifications

Who I am

About

A cybersecurity and systems engineer, I have been deploying and integrating security solutions since June 2022 for major telecom, financial and institutional accounts: Orange, Swisslife, BHCI, Coris Holding and ANPTIC, across Africa and Europe.

My core work is identity and privileged access management (IAM/PAM) and infrastructure and network security. A Wallix Certified Expert, I am equally comfortable with systems administration and virtualization and with secure delivery pipelines.

I like working autonomously on sensitive production environments, in English- and French-speaking multi-country contexts. What drives me is making systems more reliable, traceable and easy to operate, where the smallest access mistake can be costly.

Top 50 TryHackMe, Côte d'Ivoire national ranking

Education

  • Master IT · Systems, Networks & Security

    Institut Britannique de Management et de Technologie (IBM-T)

  • Bachelor · Systems & Networks Administration and Security (ASSRI)

    Université Polytechnique de Bingerville (UPB)

  • High School Diploma (Baccalauréat)

    Groupe ITA

  • Middle school

    Collège Catholique St Viateur

Languages

  • French

    Native (C2)

  • English

    C1 · technical & professional (Liberia, Botswana missions)

Interests

  • Video games
  • Football & sport
  • Manga & anime (JP/KR)
  • Music

Experience

My journey

Synelia Tech (ex Smile CI)

Sept. 2022 – Present

Cybersecurity & Systems Engineer

Abidjan, Côte d'Ivoire

IT security solutions integrator. I work on assignment across the client missions below.

Client missions delivered on assignment

Orange Liberia (OLIB) · Monrovia, Liberia

Oct. 2024 – Present

Fully English-speaking environment, critical production infrastructure.

  • Active Directory management: accounts, GPO, security policies, AD forensics.
  • Access provisioning and automation with Ansible.
  • Secured CI/CD pipelines (Kubernetes, GitHub Actions, ArgoCD) and handled critical incidents.
  • Managed production SSL DigiCert certificates, configured nginx reverse proxy.
  • Migrated 20 servers from CentOS 7 to Rocky Linux 9.
  • Handled MEA SOC alerts, Centreon monitoring, Veeam backups and restores.
Active DirectoryAnsibleKubernetesArgoCDGitHub ActionsRocky LinuxCentreonVeeam

Orange Côte d'Ivoire (OCI) · Abidjan, Côte d'Ivoire

March 2023 – Present
  • Deployed and integrated Wallix Bastion in production, with continuous support.
  • Identity & access management (AD, MFA DUO Security, user rights).
  • Deployed security solutions: FortiGate firewall, WAF, web Proxy, Mail Gateway.
  • Nexpose and Metasploit vulnerability audits, documentation and acceptance tests.
  • Trained client teams and mentored interns.
Wallix BastionFortiGateDUO MFAWAFActive Directory

Missions internationales · Afrique & Europe

Sept. 2022 – Present

Swisslife France · Orange Burkina · Central African Rep. · Senegal · GOS · BHCI · Coris Holding · ANPTIC · Botswana (remote).

  • Swisslife France (Paris): Wallix Bastion deployment, migration, acceptance, handover and support.
  • Orange Burkina Faso: Wallix Bastion deployment and DNS platform migration.
  • Orange Central African Rep. & Senegal: Wallix Bastion deployment and post-go-live support.
  • BHCI (banking) & Coris Holding: PAM deployment in financial environments.
  • ANPTIC Burkina Faso: designed and deployed a PROD/DR private cloud with Proxmox VE.
  • Orange Botswana: remote Wallix Bastion technical support, in English.
Wallix BastionProxmox VEDNSPAMPRA/DR

Synelia Tech (ex Smile CI)

June 2022 – Sept. 2022

Systems & Security Administrator Intern

Abidjan, Côte d'Ivoire

  • Deployed a high-availability Proxmox VE cluster (PVE / PMG / PBS).
  • Set up a VMware virtual infrastructure, internal R&D and Wallix projects.
Proxmox VEVMwareWallix Bastion

All engagements carried out under strict client confidentiality and non-disclosure agreements (NDA).

Technical expertise

My skills

IAM / PAM

  • Wallix Bastion (WCE-P)
  • Active Directory / GPO / LDAP
  • MFA DUO Security / 2FA
  • RBAC & politiques de sessions
  • Rotation & coffre-fort de mots de passe

Network security

  • FortiGate
  • pfSense
  • WAF / Proxy web
  • VPN IPSec / VLAN
  • Mail Gateway
  • nginx reverse proxy

Systems & Virtualization

  • Linux (Rocky, Ubuntu, Debian)
  • Proxmox VE (PVE / PMG / PBS)
  • VMware vSphere
  • Windows Server / SQL Always On

Automation & CI/CD

  • Ansible (playbooks, rôles)
  • Docker
  • Kubernetes / ArgoCD
  • GitHub Actions
  • Bash / Python

Audit & Incident Response

  • Nexpose / OpenVAS / Metasploit
  • OWASP · SAST / DAST
  • Réponse à incident SOC (MEA)
  • Forensique Active Directory

Monitoring, backup & PKI

  • Centreon (supervision)
  • Veeam Backup & Replication
  • PKI · SSL/TLS · DigiCert · OpenSSL
  • Plans de reprise (PRA/DR)

Skills in action

Areas of expertise

IAM/PAMTélécomFinanceAssurance

Privileged Access Management (PAM)

Deployment and industrialization of Wallix Bastion on critical infrastructure, from telecom to banking and insurance, from design to acceptance and knowledge transfer.

  • Wallix Bastion architecture and production deployment
  • Password vault, automatic rotation and secrets management
  • Active Directory / LDAP integration, MFA (DUO) and RBAC
  • Session policies, recording and traceability for compliance
  • Acceptance testing, technical documentation and team training
Wallix BastionActive DirectoryDUO MFALDAPRBAC
InfrastructureCloud privéVirtualisation

Private cloud, virtualization & DR

Design and operation of high-availability virtualized infrastructure, with a disaster-recovery plan, on a mastered open-source stack.

  • High-availability Proxmox VE clusters (PVE / PMG / PBS)
  • PROD/DR architecture design and disaster-recovery planning
  • Backup and restore (Veeam, PBS)
  • Shared storage, clustering and monitoring
  • Server fleet migration (CentOS to Rocky Linux)
Proxmox VEClusteringVeeamRocky LinuxPRA/DR
RéseauSécuritéPare-feu

Network & perimeter security

Set-up and administration of the network and perimeter security stack on production environments.

  • FortiGate firewalls: filtering policies, NAT, application control
  • WAF, web proxy and mail gateway
  • IPSec VPN, VLAN segmentation and SSL/TLS inspection
  • nginx reverse proxy and application publishing
  • Vulnerability audits (Nexpose, Metasploit) and acceptance test plans
FortiGateWAFProxyMail GatewayVPN IPSec
DevSecOpsInfrastructureAutomatisation

DevSecOps & infrastructure hardening

Securing delivery pipelines and systems infrastructure, without slowing down releases.

  • CI/CD pipeline hardening (Kubernetes, GitHub Actions, ArgoCD)
  • Access automation and provisioning with Ansible
  • SSL certificate management (DigiCert), PKI and reverse proxy
  • Active Directory administration: accounts, GPO, forensics
  • Monitoring (Centreon) and incident response
KubernetesGitHub ActionsArgoCDAnsiblenginx

Contact

Get in touch

Yann-Désiré Kouassi

Cybersecurity Engineer · IAM/PAM & systems

A cybersecurity or infrastructure project to run? That's exactly my field. Drop me a line, let's talk.

Send an email